R3303-HP HSR6800 Routers Security Configuration Guide

330
[RouterB] public-key local create rsa
The range of public key size is (512 ~ 2048).
NOTES: If the key modulus is greater than 512,
It will take a few minutes.
Press CTRL+C to abort.
Input the bits of the modulus[default = 1024]:
Generating Keys...
++++++++++++++++++++++++
+++++++++++++++++++++++
+++++
+++++
# Generate a DSA key pair.
[RouterB] public-key local create dsa
The range of public key size is (512 ~ 2048).
NOTES: If the key modulus is greater than 512,
It will take a few minutes.
Press CTRL+C to abort.
Input the bits of the modulus[default = 1024]:
Generating Keys...
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++++++++++++++++++++++++++++++++
# Enable the SSH server function.
[RouterB] ssh server enable
# Configure an IP address for interface GigabitEthernet 3/0/1. The Stelnet client uses this IP
address as the destination address for SSH connection.
[RouterB] interface gigabitethernet 3/0/1
[RouterB-GigabitEthernet3/0/1] ip address 192.168.1.40 255.255.255.0
[RouterB-GigabitEthernet3/0/1] quit
# Set the authentication mode for the user interface to AAA.
[RouterB] user-interface vty 0 4
[RouterB-ui-vty0-4] authentication-mode scheme
# Enable the user interface to support SSH.
[RouterB-ui-vty0-4] protocol inbound ssh
[RouterB-ui-vty0-4] quit
# Create local user client001, with the password as aabbcc and service type as ssh.
[RouterB] local-user client001
[RouterB-luser-client001] password simple aabbcc
[RouterB-luser-client001] service-type ssh
[RouterB-luser-client001] quit
# Specify the service type for user client001 as stelnet, and the authentication method as password.
(Optional. If an SSH user is not created, password authentication is used by default.)
[RouterB] ssh user client001 service-type stelnet authentication-type password
2. Establish a connection to the Stelnet server:
# Configure an IP address for interface GigabitEthernet 3/0/1.
<RouterA> system-view
[RouterA] interface gigabitethernet 3/0/1
[RouterA-GigabitEthernet3/0/1] ip address 192.168.1.56 255.255.255.0